
androwarn
Yet another static code analyzer for malicious Android applications

Yet another static code analyzer for malicious Android applications

Detects PowerShell-based malware artifacts from event logs and performs static analysis on PowerShell scripts to identify malicious activity.

Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators…

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Offline checker for Thymeleaf CVE-2026-40477 / CVE-2026-41901 — tells you which of the two CVSS 9.0 SSTI flaws you are exposed to, and whether your…

Resources related to GitHub Security Lab

Select Bugs From Binary Where Pattern Like CVE-1337-Days

Interactive documentation and visual reference for binary formats and system memory layouts.

A Public Package Scanner for The Community

IDA plugins and scripts for analyzing register usage frame

Automatic security vulnerability remediation for your code.

A disassembler & experimental decompiler for TLOU2 DC Scripts.

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

Benchmark measuring AI models' ability to detect vulnerabilities in source code via real bug bounty cases with balanced recall and false-positive…

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

Markdown XSS leads to RCE in VNote version <=3.18.1

Using Struts2 and PowerShell to recreate CVE-2017-5638 OGNL Injection vulnerability.

Scans an executable and determines if it was wrapped in an Electron version vulnerable to the Chromium vulnerability CVE-2023-4863/ CVE-2023-5129